mediumMultiple Choice
350-401 Practice Question: Interface GigabitEthernet0/0 ip address 10.0.0.1…
interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.0 ip nat outside
!
interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ip nat inside
!
access-list 1 permit 192.168.1.0 0.0.0.255
!
ip nat inside source list 1 interface GigabitEthernet0/0 overload
What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the distinction between dynamic NAT (one-to-one, limited by pool size) and PAT (many-to-one, using port multiplexing), and candidates mistakenly think that 'overload' still limits translation to one host at a time or that the access list must be applied to an interface for NAT to work.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All traffic from 192.168.1.0/24 will be translated to the IP address of GigabitEthernet0/0 using PAT.
This configuration uses dynamic NAT with Port Address Translation (PAT), also known as NAT overload. The `ip nat inside source list 1 interface GigabitEthernet0/0 overload` command translates all source IP addresses matching access-list 1 (the 192.168.1.0/24 subnet) to the single IP address of the outside interface (10.0.0.1), using unique source port numbers to differentiate multiple simultaneous sessions. This allows all hosts in the inside network to share the single public IP address for internet access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
All traffic from 192.168.1.0/24 will be translated to the IP address of GigabitEthernet0/0 using PAT.
Why this is correct
This statement is correct. The 'overload' keyword makes the router perform Port Address Translation (PAT), where all hosts from the 192.168.1.0/24 network that are matched by the access list have their source IP addresses translated to the IP address configured on GigabitEthernet0/0. Unique source port numbers are assigned to each concurrent connection, allowing many internal hosts to share the single public interface IP.
- ✗
Only one host from 192.168.1.0/24 can access the internet at a time.
Why it's wrong here
This is incorrect because PAT does not restrict connectivity to a single host; it multiplexes thousands of connections by tracking the source IP and Layer 4 port of each flow inside the NAT translation table. Since the access list matches the entire 192.168.1.0/24 subnet, every host is eligible for translation, and each host can establish multiple simultaneous sessions using different port numbers, so many hosts can access the internet concurrently.
- ✗
Traffic from the outside interface will be translated to 192.168.1.0/24.
Why it's wrong here
This is incorrect because the command 'ip nat inside source list' configures source NAT, which translates the source address of packets arriving on the inside interface from 192.168.1.0/24 to the public IP of GigabitEthernet0/0. For traffic coming from the outside to be translated to the 192.168.1.0/24 network, you would need a destination NAT or an 'ip nat outside source' statement; the configuration shown has no such directionality.
- ✗
The configuration will fail because the access list must be applied to an interface.
Why it's wrong here
This is incorrect because the access list referenced by the NAT configuration is used internally to classify traffic for translation; it is not a traffic-filtering ACL that must be attached to an interface with 'ip access-group'. The 'ip nat inside source list 1 interface gigabitEthernet0/0 overload' command automatically ties the ACL to the NAT process, so applying it to an interface is unnecessary and would be a different feature.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.